Executive brief
Kingdom Communication Associated manufactures Smart Video Intercom Systems used for building entry and communication management. CVE-2026-89173 allows unauthenticated remote attackers to enumerate valid user accounts by observing differences in system responses, potentially facilitating targeted account compromise. This information disclosure can be chained with brute-force attacks to gain unauthorized access to the system.
Technical details
CVE-2026-89173 is a user account enumeration vulnerability affecting Kingdom Communication Associated Smart Video Intercom Systems. Unauthenticated remote attackers can exploit timing or response differences in the authentication mechanism to determine which user accounts exist on the system, without requiring any credentials or authentication. The vulnerability is network-reachable with no user interaction required. Enumeration of valid accounts reduces the attacker's search space and enables targeted brute-force attacks (as noted in the related CVE-2026-89174). Patches are available: update EH3040, EH4200, EH1000B, and EH2070 to versions 2.5.0A, 2.5.0A, 2.7.0A, and 2.8.0A respectively.
Affected products
- Kingdom Communication Associated Smart Video Intercom System EH3040 before 2.5.0A
- Kingdom Communication Associated Smart Video Intercom System EH4200 before 2.5.0A
- Kingdom Communication Associated Smart Video Intercom System EH1000B before 2.7.0A
- Kingdom Communication Associated Smart Video Intercom System EH2070 before 2.8.0A
Timeline
- 2026-09-11: disclosed